Cisco User-Changeable Password (UCP)...

- AV AC AU C I A
发布: 2008-03-12
修订: 2025-04-13

Cisco User-Changeable Password (UCP) is prone to multiple remote vulnerabilities, including cross-site scripting and buffer-overflow vulnerabilities. Exploiting the cross-site scripting issues may help the attacker steal cookie-based authentication credentials and launch other attacks. Exploiting the buffer-overflow vulnerabilities allows attackers to execute code in the context of the affected application, facilitating the remote compromise of affected computers. The buffer-overflow issues are tracked by Cisco Bug ID CSCsl49180. The cross-site scripting issues are tracked by Cisco Bug ID CSCsl49205. These issues affect versions prior to UCP 4.2 when running on Microsoft Windows.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息
", "id": "REF_*_/archive/1/489463", "level": 2}, {"image": "../../static/img/aqua/lianjie.png", "connections": ["VHN-288071"], "color": {"background": "#cde0ff", "border": "#006cf9", "highlight": {"background": "#fff", "border": "black"}}, "shape": "circularImage", "label": " Cisco Systems Product Security Incident Response Team ", "id": "REF_*_/archive/1/489460", "level": 2}]'>